PT-2026-98890 · Piwigo · Piwigo
CVE-2026-42322
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Piwigo versions prior to 16.4.0
Description
In the 'admin/themes standard pages.php' endpoint, the application validates uploaded logo content by MIME type but uses the attacker-controlled
std pgs logo extension when creating the stored filename. An authenticated administrator can upload image content with a server-executable extension, allowing the file to be stored in a web-accessible directory and executed by the web server. This can lead to arbitrary command execution, data disclosure, modification, persistence, and service disruption.Recommendations
Update to version 16.4.0.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Piwigo